Package 1 · Services
Architecture review
For organisations whose IT grew over years and where nobody has the full picture any more.
A defensible assessment of your architecture with a prioritised action list.
How you know you need this
The IT landscape grew over years: grown networks, several cloud connections, systems nobody fully oversees. Every change takes longer than it used to, and nobody can say whether the landscape still holds.
Architecture diagrams exist, but they do not match what actually runs. Decisions are therefore made on gut feeling – or not at all, because the basis is missing.
Management asks for a defensible assessment and you do not want to answer with assumptions. Or an audit is coming and you want to know where you stand beforehand.
What you get
- Capture of the actual estate: systems, interfaces, dependencies, operational boundaries.
- Assessment against a target architecture and against the rules that apply to you (such as BSI IT baseline protection, ISO 27001, KRITIS, VS-NfD).
- Prioritised action list: what must come first, what can wait, what each decision costs.
- Target architecture sketch that can be reached in stages – not a wish list, but with intermediate steps.
- Decision paper for management: one page that stands without prior knowledge.
- Closing session with your business units, explaining the findings and answering questions.
How long it takes
Usually four to eight weeks, depending on the size of the landscape. The inventory runs alongside your operations.
What you contribute
Access to documentation and systems, one technical contact per domain, two to three half-day sessions.
What is not included
Implementing the actions. Whoever assesses should not sell the same actions – for that reason implementation is explicitly not part of this package.
Common questions
Do we have to disclose everything?
No. We agree beforehand which areas are in scope. The scope can start small and grow later.
Do we get a document we can reuse internally?
Yes. The report is written so that management can decide with it and your team can work with it. It is not a report for the drawer.
What if we do not implement the actions immediately?
Nothing. The prioritisation tells you what is urgent and what can wait. You set the pace, not the report.
Initial call
In the first call we clarify whether the package fits your situation. Then you get two proposed dates and a clear statement on effort.
Other packages
- Project and sub-project management – For undertakings that need one accountable person – not another supplier.
- Interim: lead architect / platform operations lead – For vacancies that operations cannot wait for.
- AI architectures and automation – For organisations that must run AI in their own network – without cloud and without outside access.
- IT audit, DORA and ICT risk management – For financial entities and regulated organisations that must be audit-ready.
- Training and seminars – For teams that should be able to do it themselves afterwards.
Contact
Request an initial call
Describe your situation in three sentences. I usually reply within one business day with an assessment and two time slots.